← Back to Feed
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
August 17, 2026 · Dark Reading · Severity: HIGH
The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.
Key Takeaways
- The Evooo1Bot Linux botnet expands beyond DDoS to include exploitation modules and credential theft capabilities.
- It adds reverse SOCKS relays to turn compromised devices into persistent attacker-controlled infrastructure for long-term access.
- This evolution represents a significant escalation in the threat posed by Mirai-derived botnet variants in the wild.